Closed govert closed 2 years ago
Struggling with my software being detected due to this too. Can this be solved please?
Thank you. It will be resolved soon. Additional context: https://0xc0decafe.com/malware-analyst-guide-to-pe-timestamps/
Thank you!
I've recently run to this indicator: https://github.com/ditekshen/detection/blob/25055fe48da0057b064a59615662fba7f8d3718b/yara/indicator_suspicious.yar#L1045
The check is not (or no longer) an appropriate one. The indicator is expected for PE files compiled with recent Windows 10 SDKs. See this discussion: https://devblogs.microsoft.com/oldnewthing/20180103-00/?p=97705